Merge pull request #980 from jstnk9/sidewinder-update

update sidewinder information
This commit is contained in:
Alexandre Dulaunoy 2024-06-02 09:29:08 +02:00 committed by GitHub
commit ab6be85bc0
No known key found for this signature in database
GPG key ID: B5690EEEBB952194

View file

@ -8967,6 +8967,19 @@
{
"description": "An actor mainly targeting Pakistan military targets, active since at least 2012. We have low confidence that this malware might be authored by an Indian company. To spread the malware, they use unique implementations to leverage the exploits of known vulnerabilities (such as CVE-2017-11882) and later deploy a Powershell payload in the final stages.",
"meta": {
"country": "IN",
"cfr-suspected-state-sponsor": "India",
"cfr-suspected-victims": [
"China",
"Pakistan",
"Nepal",
"Afghanistan"
],
"cfr-target-category": [
"Government",
"Military",
"Private Sector"
],
"refs": [
"https://securelist.com/apt-trends-report-q1-2018/85280/",
"https://blog.trendmicro.com/trendlabs-security-intelligence/first-active-attack-exploiting-cve-2019-2215-found-on-google-play-linked-to-sidewinder-apt-group/",